Security - what security?
Posted in 2005
Topics: Connectivity: ODBC / JDBC / .NET, Security, Permissions & Auditing, Platform-Specific Issues, Versions, Editions & End-of-Life
I've been doing some investigation into a little problem with privileges. And this is what I have found. If you want to access an Informix database via ODBC and your normal login and password are restricted then set up your odbc connection with no user name and password and you can do anything. This is what I did to prove it. 1. I created a new database called security. 2. I added two tables - opentab and securetab 3. I revoked all permissions on securetab from public 4. I granted connect to public. 5. From MS-Access I set up a new database 6. I used "link-tables" to add a new odbc connection with no username or password, and to link both tables. 7. I could SELECT, INSERT, UPDATE, and DELETE from both tables. 8. I then deleted both tables from my access database. and used control panel to remove the odbc connection. 9. I then repeated steps 5-7 but with a valid username and password. 10. I couldn't access the securetab. So, using a username and password is secure but not using a username and password gives full access. Can anybody spot anything wrong in my reasoning? BTW I have done this on IDS 9.4, running on AIX 5.2, and I was running Windows XP with MS-Access 2002 SP3, and Informix-Client SDK version 2.81 regards Malcolm
mweallans@panacea.co.uk wrote: > I've been doing some investigation into a little problem with > privileges. And this is what I have found. > > If you want to access an Informix database via ODBC and your normal > login and password are restricted then set up your odbc connection with > no user name and password and you can do anything. > > This is what I did to prove it. > > 1. I created a new database called security. > 2. I added two tables - opentab and securetab > 3. I revoked all permissions on securetab from public > 4. I granted connect to public. > 5. From MS-Access I set up a new database > 6. I used "link-tables" to add a new odbc connection with no username > or password, and to link both tables. > 7. I could SELECT, INSERT, UPDATE, and DELETE from both tables. > 8. I then deleted both tables from my access database. and used control > panel to remove the odbc connection. > 9. I then repeated steps 5-7 but with a valid username and password. > 10. I couldn't access the securetab. > > So, using a username and password is secure but not using a username > and password gives full access. > > Can anybody spot anything wrong in my reasoning? > > BTW I have done this on IDS 9.4, running on AIX 5.2, and I was running > Windows XP with MS-Access 2002 SP3, and Informix-Client SDK version > 2.81 > > regards > > Malcolm > You probably have the info in SetNet32... Is the DB on the same machine as the client? Informix uses OS authentication... not sure about what happens in windows, but if you have a sessin on the operating system you are authenticated on the DB. And if you're making tests with a priviledge user... As a last resort try contacting IBM for getting an explanation. Regards.
> You probably have the info in SetNet32... Is the DB on the same machine > as the client? Informix uses OS authentication... not sure about what > happens in windows, but if you have a sessin on the operating system you > are authenticated on the DB. And if you're making tests with a > priviledge user... > > As a last resort try contacting IBM for getting an explanation. Yes, if you've set up a user and password in setnet32 it could explain it. Otherwise if IDS is on AIX and the client on Windows, and you haven't compromised security with hosts.equiv or .rhosts entries on the server there shouldn't be any way to connect without a userid and password. There are a couple of bugs in this area associated with local connections (client and server on same machine or ssh session on remote machine). If your connection is local ask tech support for a fix to bugs 169201 and 169263, which are fixed in 9.40.xC6 and 10.00.xC1. Regards Guy Fernando Nunes wrote: > mweallans@panacea.co.uk wrote: > >> I've been doing some investigation into a little problem with >> privileges. And this is what I have found. >> >> If you want to access an Informix database via ODBC and your normal >> login and password are restricted then set up your odbc connection with >> no user name and password and you can do anything. >> >> This is what I did to prove it. >> >> 1. I created a new database called security. >> 2. I added two tables - opentab and securetab >> 3. I revoked all permissions on securetab from public >> 4. I granted connect to public. >> 5. From MS-Access I set up a new database >> 6. I used "link-tables" to add a new odbc connection with no username >> or password, and to link both tables. >> 7. I could SELECT, INSERT, UPDATE, and DELETE from both tables. >> 8. I then deleted both tables from my access database. and used control >> panel to remove the odbc connection. >> 9. I then repeated steps 5-7 but with a valid username and password. >> 10. I couldn't access the securetab. >> >> So, using a username and password is secure but not using a username >> and password gives full access. >> >> Can anybody spot anything wrong in my reasoning? >> >> BTW I have done this on IDS 9.4, running on AIX 5.2, and I was running >> Windows XP with MS-Access 2002 SP3, and Informix-Client SDK version >> 2.81 >> >> regards >> >> Malcolm >> > > > Regards.